Overview
The Incydr Agent Risk Center identifies AI tools in use across your environment to show you a complete inventory of AI applications, AI browser destinations, and the users engaging with them throughout your organization. Specifically, Agent Risk Center:
- Leverages the insider risk agent and Incydr browser extension to automatically detect the AI agents and tools already operating in your environment, with no manual inventory or setup required.
- Brings visibility to AI activity across your organization that may otherwise go undetected.
- Attributes AI agent activity to individual users, so risk can be evaluated based on who is behind the activity, not just the activity itself.
- Enables you to approve, monitor, or block usage for each AI tool.
Considerations
- Agent Risk Center requires insider risk agent version 2.8.0 or later, and the most recent Incydr browser extension.
- Agent Risk Center is currently available as a limited access beta release. Contact your account team if you are interested in participating in the beta.
- Required permissions:
- To view Agent Risk Center, you must have one of the following roles: Insider Risk Read Only, Insider Risk Admin, Security Center User, Insider Risk Analyst, or Customer Cloud Admin.
- To create or edit AI Rulebook rules, you must have one of the following roles: Insider Risk Admin or Customer Cloud Admin.
Agent Risk Center
Agent Risk Center contains three main components:
- AI Inventory: Lists all AI applications, AI browser destinations, and users engaging with AI tools.
- Usage Matrix: Shows AI tool adoption across departments, including whether a tool is approved or not. This usage data helps you see where risk is concentrated to better prioritize response efforts.
- AI Rulebook: Shows which AI tools are sanctioned, unsanctioned, and any associated blocking rules. Each rule targets a specific AI tool, applies to the users you specify, and can optionally block unsanctioned usage. For example, an AI tool can be approved for use with one group of users but blocked for everyone else.
AI Inventory
AI Inventory shows AI activity for all users, applications, and browser destinations in your environment. Details about each section are listed below.
Users
The Users tab shows which AI tools users have installed and how those tools are classified in your AI Rulebook. This enables you to quickly see who represents greater risk by using non-sanctioned AI tools.
To view user details:
- Sign in to the Incydr console.
- Go to Agent Risk Center > AI Inventory.
- Select Users.
|
Item |
Description |
|
| a | Users with AI apps installed | Count of users with at least one AI desktop application detected on their endpoint. |
| b | Users with unsanctioned or undecided AI tools | Count of users whose AI tool usage includes at least one application classified as Unsanctioned or Undecided. Click View users to filter the list below to these users. |
| c | Avg tools per user | Average number of distinct AI tools detected per user, across all users with at least one AI tool. |
| d | Search | Enter a full or partial username to filter the list of users below. |
| e | Filter | Refine results by the user's department and the app classification (sanctioned, unsanctioned, undecided). |
| f | User | The user's name and job title. |
| g | Department | The user's department, as indicated by your identity provider. |
| h | Endpoint apps |
A summary of the AI applications detected on the user's endpoint, with a count for each category of app:
|
| i | Unsanctioned + undecided |
The total number of AI tools in use by this user that are classified as either Unsanctioned or Undecided. Users with higher counts may present a greater risk. Click the column name to sort by number of apps. |
| j | View details |
Click to view more details about the user, including:
|
Applications
The Applications tab displays usage data for each AI tool, how each app is classified, and if AI Rulebook rules are actively blocking an app.
To view application details:
- Sign in to the Incydr console.
- Go to Agent Risk Center > AI Inventory.
- Select Applications.
|
Item |
Description |
|
| a | Total AI desktop apps detected | Count of distinct AI desktop applications detected across all endpoints. |
| b | Endpoints with at least one AI app | Count of endpoints with at least one detected AI application. |
| c | Undecided apps awaiting review | Count of detected applications that have not yet been classified as Sanctioned or Unsanctioned in your AI Rulebook. |
| d | Search | Enter a partial or full application name to filter results in the list below. |
| e | Expand all / Collapse all | Click to expand or collapse AI Rulebook details for each app. |
| f | Filter | Refine results by app classification (sanctioned, unsanctioned, or undecided). |
| g | Application |
Name of the detected AI app. For apps with at least one AI Rulebook entry, click to view more details, including:
|
| h | Confirmed AI app |
Indicates whether the application has been verified as an AI tool.
AI Rulebook entries only support Confirmed apps. Apps categorized as Likely cannot be included in the AI Rulebook. |
| i | Status | The application's AI Rulebook classification: Sanctioned, Unsanctioned, or Undecided. An application can show more than one status if different Rulebook rules apply to different scopes (for example, sanctioned for one department and unsanctioned for another). |
| j | Endpoints | Number of distinct user devices with the application installed. |
| k | Users | Number of distinct users with the application installed. |
| l | View details |
Click to view more details about the application, including:
|
Browser destinations
The Browser destinations tab shows file upload and paste activity to AI websites for all users in your environment.
To view browser destination details:
- Sign in to the Incydr console.
- Go to Agent Risk Center > AI Inventory.
- Select Browser destinations.
|
Item |
Description |
|
| a | Date range | Specify the date range for data returned on this page. |
| b | AI sites detected in the browser | Count of distinct AI websites detected across your organization. |
| c | Files uploaded to AI sites | Number of files uploaded to AI sites during the selected date range. |
| d | Pasted events to AI sites | Number of paste events to AI sites during the selected date range. |
| e | Browser destinations with unsanctioned use | Count of browser destinations with at least one Unsanctioned classification. |
| f | Search | Enter a full or partial name to filter the list by browser destination name. |
| g | Filter |
Refine results by Sanctioned and Unsanctioned. Sanctioned and unsanctioned status for browser destinations is based on Trusted activity settings, not the AI Rulebook. |
| h | Browser destination | The name and URL of the AI site. |
| i | Status |
Indicates the app classification based on your trusted activity settings.
A destination can be categorized as both sanctioned and unsanctioned depending on specific usage. For example, activity on chatgpt.com could be sanctioned (trusted) for users signed in with a corporate account, but unsanctioned (not trusted) for users signed in with a personal account. |
| j | Users | Number of distinct users who have uploaded or pasted to the destination. |
| k | Files Uploaded | Number of files uploaded to the destination. |
| l | Blocked uploads | Number of blocked upload attempts to the detstination. |
| m | Pasted to browser | Number of paste events to the destination. |
| n | Blocked pastes | Number of blocked paste attempts to the destination. |
| o | View details | Click to view more details about the browser destination. |
Sanctioned and unsanctioned status for browser destinations is based on Trusted activity settings, not the AI Rulebook.
- Sanctioned activity matches a trusted activity entry. Unsanctioned activity does not match a trusted activity entry.
- To block browser destinations, use the Block destinations preventative controls, not the AI Rulebook.
Usage Matrix
The Usage Matrix shows AI tool use across departments, categorized by sanctioned, unsanctioned, and undecided tools. This data helps you see where risk is concentrated to better prioritize response efforts.
To view usage matrix details:
- Sign in to the Incydr console.
- Go to Agent Risk Center.
- Select Usage Matrix.
- (Optional) Select a specific date range. By default, the matrix shows the last 180 days.
- Review usage data by app and department. Click any cell in the matrix for more details about usage.
|
Item |
Description |
|
| a | Date range | Specify the date range for data returned on this page. |
| b | Filter | Refine results by Sanctioned, Unsanctioned, and Undecided AI tool use. |
| c | Search | Enter a full or partial name to filter results by app or browser destination name. |
| d | AI tool | Indicates the name and classification of each AI tool. Desktop apps appear first, then browser destinations. Depending on the number of detected AI tools in your environment, you may need to scroll right to see the Browser destination usage. Click the arrow next to a column header to view more details about that tool. |
| e | Department | Each row represents one department, labeled with the department name and its total user count. |
| f | User count |
The number of users in each department who used each AI tool during the specified date range. The cell color indicates the tool's classification for that department. Color intensity increases with higher number of users:
User counts only reflect users with an assigned department. Users with no department specified are not included in this Usage Matrix. |
AI Rulebook
The AI Rulebook defines which AI tools are sanctioned and unsanctioned for specific user groups. The AI Rulebook also enables you to block unsanctioned apps. Rules created here determine whether tools show as Sanctioned or Unsanctioned throughout the Agent Risk Center.
Rules are split into two tables: Sanctioned usage, for tools explicitly allowed for a defined scope, and Unsanctioned usage, for tools that are not approved. Unsanctioned rules can be configured to either block or monitor usage.
AI Rulebook considerations
- AI Rulebook entries only support apps Confirmed by Incydr as AI tools. Rules cannot be created for an app categorized as a Likely AI tool.
- AI Rulebook settings only apply to non-browser applications. To manage browser destinations, use trusted activity settings and destination blocking preventative controls.
To view AI Rulebook details:
- Sign in to the Incydr console.
- Go to Agent Risk Center.
- Select AI Rulebook.
|
Item |
Description |
|
| a | Add to rulebook | Click to create a new rule. |
| b | Sanctioned usage | Lists tools explicitly allowed for a defined scope. |
| c | Name | Name of the rule. The rule name is defined upon rule creation, but you can change the name later from the Edit view. |
| d | Tool | The AI application the rule applies to. |
| e | Scope | Who the rule applies to (for example, Everyone, or a specific department). |
| f | Status |
Indicates how you have classified this AI tool for a defined scope:
Sanctioning a tool updates its status in the Agent Risk Center for those users specified in the rule, but does not restrict access to the tool for anyone else. To restrict access to other users, create an unsanctioned rule and choose to block access to the tool. |
| g | Edit | Opens the rule for editing. |
| h | Unsanctioned usage | Lists tools explicitly not allowed for a defined scope. |
| i | Blocked | For unsanctioned tools, indicates whether the rule actively blocks usage or not. |
Create or edit a rule
- Go to Agent Risk Center > AI Rulebook.
- Select the edit icon next to an existing rule to change its scope or blocking behavior, or select Add rule to create a new rule.
- Set the following fields:
- A Name for the rule
- The Tool the rule applies to
- The Scope of users it applies to
- Whether unsanctioned usage should be Blocked or Not blocked (monitored only)
- Click Save.
The AI Inventory and Usage Matrix update to reflect the new status, and blocked applications show a Blocked badge in the inventory.
Review scope before blocking
Setting a rule to Blocked stops the application from running for every user in that rule's scope. Confirm the scope is correct before saving, especially for rules applied to Everyone.
Comments
Please sign in to leave a comment.